CVE-2026-106441

high

Description

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who controls Hydra logging configuration can therefore select an importable class or factory and cause it to be invoked with the application's privileges, even in versions where instantiate() is protected because the logging path does not use instantiate(). This issue is fixed in versions 1.3.6 and 1.4.0.dev9.

References

https://github.com/hydra-ecosystem/hydra/security/advisories/GHSA-c3wx-c55w-pxjq

https://github.com/hydra-ecosystem/hydra/releases/tag/v1.3.6

https://github.com/hydra-ecosystem/hydra/pull/3420

https://github.com/hydra-ecosystem/hydra/commit/ff3e4dba890c29a21d8c2bb867ee87d37ccf21d0

https://github.com/hydra-ecosystem/hydra/commit/76bfc30ce1f3105416941dd2e3a562568e369120

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93664

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00167